正解:A
Federated Identity Management (FIM) is designed to allow users to access multiple, separate systems using a single set of credentials, usually managed through trust relationships between Identity Providers (IdPs) and Service Providers (SPs). This process enables Single Sign-On (SSO) across cloud and on-premise services, reducing password fatigue and improving administrative efficiency.
Key federation protocols such as SAML, OAuth, and OpenID Connect are standard in establishing secure identity federation. FIM is especially beneficial in hybrid and multi-cloud environments where users must access numerous services seamlessly.
This is emphasized inDomain 12: Identity, Entitlement, and Access Managementof the CCSK guidance, which highlights how identity federation enhances user experience, improves security, and enables scalability.
Reference:CSA Security Guidance v4.0 - Domain 12: Identity, Entitlement, and Access ManagementCSA Cloud Controls Matrix v3.0.1 - IAM-06: Federation & Single Sign-On